CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2021-32590

CVSS 9.9v3.1pub. 2021-08-04upd. 2024-11-21

Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on the underlying SQL database via specifically crafted HTTP requests.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Fortinet Fortiportal

    APP
    Fortinet
    3.2.0 – 3.2.24.0.0 – 4.0.44.1.0 – 4.1.24.2.0 – 4.2.45.0.0 – 5.0.35.1.0 – 5.1.25.2.0 – 5.2.6 (excl.)5.3.0 – 5.3.6 (excl.)6.0.0 – 6.0.5 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2021-32588CRITICAL9.8PL ✓same product

Zakodowane na stałe poświadczenia w Fortinet FortiPortal umożliwiają RCE jako root

CVE-2017-7342CRITICAL9.8PL ✓same product

Słaby mechanizm odzyskiwania hasła w Fortinet FortiPortal umożliwia nieautoryzowane wykonanie kodu

CVE-2017-7337CRITICAL9.1PL ✓same product

Nieprawidłowa kontrola dostępu w Fortinet FortiPortal — dostęp do nieautoryzowanych VDOM/ADOM

CVE-2025-24470HIGH8.6same product

An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 th...

CVE-2021-32589HIGH8.1same product

A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7...